CVE-2020-24948
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 13.14% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- autoptimize/autoptimize
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/160850/WordPress-Autoptimize-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10372Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/160850/WordPress-Autoptimize-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10372Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.